malloy-html-data-apps

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions proactively address security by mandating the use of createElement and textContent for data rendering. It explicitly forbids the use of innerHTML, insertAdjacentHTML, or document.write with data-derived strings to prevent Cross-Site Scripting (XSS) attacks.
  • [COMMAND_EXECUTION]: The skill utilizes standard development commands for its primary purpose, including npx @malloy-publisher/server to run a local development environment and python3 -m http.server for a verification harness. These commands are executed locally for authoring and testing purposes.
  • [EXTERNAL_DOWNLOADS]: The skill references the @malloy-publisher/server package via npx. This is a vendor-owned resource corresponding to the skill author 'malloydata' and is consistent with the skill's functionality for serving Malloy applications.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes external data from Malloy models, it provides robust remediation guidance by requiring developers to use DOM-safe methods (textContent) for all data interpolation, effectively sanitizing the output surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:02 AM
Security Audit — agent-trust-hub — malloy-html-data-apps